Junglewise Threat Intelligence

CVE-2024-8069: Citrix Session Recording deserialization of untrusted data

CVE-2024-8069 · Severity: critical · CVSS 8 · Exploited in the wild · Published 2025-08-25

Vendors: Citrix.

Executive brief

Citrix Session Recording is a tool used by organizations to monitor and record user activity in virtual desktop environments for compliance and security auditing. A vulnerability in this software could allow an authorized user on the internal network to execute malicious code on the recording server. This could lead to unauthorized access to sensitive session data or a disruption of the auditing service.

Technical details

A deserialization of untrusted data vulnerability (CWE-502) exists in Citrix Session Recording. The flaw allows an attacker to achieve remote code execution with the privileges of the NetworkService account. Exploitation requires the attacker to be authenticated and located on the same intranet (adjacent network) as the target server. The vulnerability has been observed being exploited in the wild. Citrix has released updates to address this issue, and users are advised to upgrade to version 2407 or the latest cumulative updates for LTSR versions.

Affected products

  • Citrix Session Recording Versions before 2407; 1912 LTSR; 2203 LTSR; 2402 LTSR

Timeline

  • 2025-08-25: disclosed
  • 2025-08-25: kev added: Added to CISA KEV catalog
  • 2025-08-25: exploited: Reported as exploited in the wild in CISA KEV catalog

Related threats